Description
Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds write in the Intel Slim Bootloader firmware. Because the flaw is triggered by a local privileged user executing a low‑complexity attack, it can potentially lead to a failure of the boot process, effectively denying system availability. The CVE description states a low availability impact and no effect on confidentiality or integrity, which means that an attacker would likely aim to stop the system from booting rather than tampering with data.

Affected Systems

Intel devices that ship with the Slim Bootloader firmware are affected. No particular firmware revisions are listed in the advisory, so all current firmware deployments should be considered vulnerable until a vendor fix is applied.

Risk and Exploitability

The CVSS score of 1.8 indicates a low severity, and the EPSS score of less than 1 % suggests a very low likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. Since the exploitation requires local privileged access, the attack surface is limited to environments where such privileges exist. Overall, the risk remains low, though a denial of service at boot time could disrupt mission‑critical operations.

Generated by OpenCVE AI on August 12, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Intel Slim Bootloader firmware update that patches the out‑of‑bounds write bug.
  • Restrict privileged access to firmware update tools to a minimum set of trusted administrators.
  • Monitor boot logs for abnormal termination or failure events to detect potential exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel slim Bootloader
Vendors & Products Intel
Intel slim Bootloader

Wed, 12 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Slim Bootloader Out‑of‑Bounds Write Leading to Denial of Service

Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Intel Slim Bootloader
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:24:48.294Z

Reserved: 2026-03-13T03:00:21.520Z

Link: CVE-2026-25194

cve-icon Vulnrichment

Updated: 2026-08-12T15:24:03.578Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:56.467

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-25194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:30:06Z

Weaknesses